diff options
| author | Eric Dumazet <eric.dumazet@gmail.com> | 2011-04-14 05:55:37 +0000 | 
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@suse.de> | 2011-04-21 14:33:00 -0700 | 
| commit | 50038a29ee9d62aba6e66109d0b9c235bc0e31e2 (patch) | |
| tree | 57cd32b7d6d5731dcd19ac5afffaf56b5c337e4e | |
| parent | 6935b2f7905bc973676cec541c1ebbbd3bd5692f (diff) | |
ip: ip_options_compile() resilient to NULL skb route
commit c65353daf137dd41f3ede3baf62d561fca076228 upstream.
Scot Doyle demonstrated ip_options_compile() could be called with an skb
without an attached route, using a setup involving a bridge, netfilter,
and forged IP packets.
Let's make ip_options_compile() and ip_options_rcv_srr() a bit more
robust, instead of changing bridge/netfilter code.
With help from Hiroaki SHIMODA.
Reported-by: Scot Doyle <lkml@scotdoyle.com>
Tested-by: Scot Doyle <lkml@scotdoyle.com>
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
Cc: Stephen Hemminger <shemminger@vyatta.com>
Acked-by: Hiroaki SHIMODA <shimoda.hiroaki@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
| -rw-r--r-- | net/ipv4/ip_options.c | 6 | 
1 files changed, 3 insertions, 3 deletions
| diff --git a/net/ipv4/ip_options.c b/net/ipv4/ip_options.c index 1906fa35860..b0413e300e5 100644 --- a/net/ipv4/ip_options.c +++ b/net/ipv4/ip_options.c @@ -329,7 +329,7 @@ int ip_options_compile(struct net *net,  					pp_ptr = optptr + 2;  					goto error;  				} -				if (skb) { +				if (rt) {  					memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);  					opt->is_changed = 1;  				} @@ -371,7 +371,7 @@ int ip_options_compile(struct net *net,  						goto error;  					}  					opt->ts = optptr - iph; -					if (skb) { +					if (rt)  {  						memcpy(&optptr[optptr[2]-1], &rt->rt_spec_dst, 4);  						timeptr = (__be32*)&optptr[optptr[2]+3];  					} @@ -603,7 +603,7 @@ int ip_options_rcv_srr(struct sk_buff *skb)  	unsigned long orefdst;  	int err; -	if (!opt->srr) +	if (!opt->srr || !rt)  		return 0;  	if (skb->pkt_type != PACKET_HOST) | 
